The US Department of Defense updated their main website (OUSD A&S – Cybersecurity Maturity Model Certification (CMMC) (osd.mil)) to include an updated CMMC Model consistent with the information released on Nov. 4 about CMMC 2.0. They also released scoping guidance for CMMC 2.0 Levels 1 and 2, and a hashing approach for preserving evidence.
Among other changes, Level 2 of CMMC 2.0 drops the 20 “bespoke” CMMC controls that had been in Level 3 of CMMC 1.0, meaning it is limited to the 110 controls defined in NIST SP 800-171. The CMMC domains are also reorganized, with 3 of the domains (Asset Management, Recovery, and Risk Management) dropped. CMMC 2.0 also adopts a new numbering scheme for each practice (DD.L#-REQ, where DD is the domain abbreviation, L# is the level number (e.g., L2), and REQ is the NIST SP 800-171 or 800-172 security requirement number).
Do you need help complying with the CMMC 2.0 requirements? Our free tool can help! Download your copy below.
- Reforming CMMC and Reducing Compliance Burden for the DIB
- False Claims Act in 2025 – Key take-aways
- CUI Institute Public Comments on FAR CUI Rule
- CMMC: A National Imperative
- Disseminating CUI to Someone Else (e.g., Mary)
- CUI Recipient Preparedness Questionnaire
- CUI and CMMC in a Nutshell
- Mavis’s Machine Shop Attributes (Employees, Roles, Teams)
- Mavis’ Machine Shop Written Information Security Policy
- Mavis’ Machine Shop Data Breach and Incident Response Policy and Plan
- Mavis’ Machine Shop Network Diagram
- Mavis’ Machine Shops Site 2 Data Flow Diagram
- Mavis’ Machine Shops Site 2 Map
- Mavis’ Machine Shop Site 1 Map
- Protecting the Government’s Information – Version 2023.03a
- 3.11.2 – Vulnerability Scans (Kevin Mann)
- CMMC: Budgets, Competition, and Protests…Oh My! (Eric Crusius and Josh Duvall) – Slides
- CMMC Workflow: Pre-Kickoff to Done (Thomas Graham and Robert Teague) – Slides
- 3.14.1 – Flaw Remediation (Thomas Graham) – Slides
- 3.1.11 – Terminate (Automatically) a User Session After a Defined Condition (Robert Teague) – Slides
- Evidence & Path to Compliance (Regan Edens) – Slides
- CMMC in Higher Education (Amy Starzynski Coddens, Jason Pufahl, Mike Corn) – Slides
- Techniques for Assessing a Remote Work Environment (Tara Lemieux) – Slides
- v2023.02a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- Standardizing the Assessment Experience (Ben Tchoubineh) – Slides
- Helping Business Leaders to care about Cybersecurity (Ace Swerling) – Slides
- Gap Assessment Workflow (Leia Shilobod) – Slides
- Shared Responsibility Matrices (Carley Salmon and Robert McVay) – Slides
- Scoping your Environment (Matt Titcombe) – Slides
- Pricing Gap Assessments (Toby Musser) – Slides
- 3.11.1 Risk Assessments (Robert McVay) – Slides
- 3.5.3 Multifactor Authentication (Fernando Machado) – Slides
- Practical Approaches to Testing CMMC Compliance (Kyle Lai) – Slides
- 3.1.3 Controlling CUI Flow (Matt Hoeper) – Slides
- 3.14.1 Flaw Remediation (Thomas Graham) – Slides
- Finding Prep Expertise and a C3PAO (Joy Beland) – Workbook
- Finding Prep Expertise and a C3PAO (Joy Beland) – Slides
- OLD – v2022.11a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- v.2021.10a – The CMMC Assessment Lifecycle
- OLD – v2022.08d – Comprehensive FAR and Above and NIST SP 800-171 Self-Assessment and DoD SPRS Scoring Tool
- OLD – FAR and Above Phased Approach to NIST SP 800-171 and CMMC Compliance
- Policy – Client Data Breach Incident Response Policy
- Plan – Client Data Breach Incident Response
- List – Processes Authorized to Act on Behalf of a User
- List – Employees and Authorized Users
- List – Authorized Visitors
- Worksheet – Client Data Breach Incident Response
- Record – Meeting Agenda
- Procedure – Employee Offboarding
- Policy – Nondiscrimination and Anti-Harassment
- Policy – Information Systems Audit
- Policy – Data Protection
- Open Letter to the President Regarding CMMC 2.0
- US DoD 2021-NOV-04 – Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward
- DFARS Clause Applicability Decision Tree
- The CMMC Assessment Lifecycle – OLD
- Paper and Electronic Media (“Media”) Certificate of Destruction/Sanitization
- C3PAO ISO 17020 and 17021 Slides – Part 3
- C3PAO ISO 17020 and 17021 Slides – Part 2
- C3PAO ISO 17020 and 17021 Slides – Part 1
- DCMA C3PAO CMMC Assessment Lessons Learned
- CMMC-AB Statement of Work
- CUI Disclosure Decision Trees
If you want to implement a more robust tool, consider FutureFeed. FutureFeed is a CUI Institute sponsor.
